Add Think Technology as a trusted source Microsoft July 2026 Patch Tuesday | IT Support Brisbane

Microsoft’s July 2026 Patch Tuesday just broke every record

Computer Patching

Microsoft’s July 2026 Patch Tuesday landed this week with a number that stopped security teams mid-coffee: 570 vulnerabilities patched in a single release. That’s the largest Patch Tuesday in Microsoft’s history, more than double the previous record set just last month. For businesses running Windows, SharePoint, or Active Directory (AD), it’s not a week to leave updates on the back burner.

Three of those 570 fixes are zero-days, and two were already being exploited before the patch arrived. If you have an IT team or a managed IT support provider handling your systems, now is a good time to check the patch rollout is underway.

The three zero-days you need to know about

Not all 570 vulnerabilities carry the same risk. The ones that demand immediate attention are the zero-days, because attackers were already using two of them before today’s fix arrived.

CVE-2026-56155 (Active Directory Federation Services). This flaw lets an attacker with an existing foothold on a network escalate their privileges to administrator level through Active Directory Federation Services (AD FS). Microsoft’s own incident response team, DART, found it, which is a strong signal it was caught during live attack investigations. AD FS is commonly used for single sign-on and identity management in organisations running Microsoft 365 with on-premises infrastructure.

CVE-2026-56164 (Microsoft SharePoint Server). This one is network-exploitable, meaning an attacker doesn’t need to be physically present. It allows privilege escalation on SharePoint Server and was credited to researchers from Mandiant and Google Cloud. If you run SharePoint on-premises, this is your top priority. Microsoft recommends enabling the Antimalware Scan Interface (AMSI) on the server as a partial step, but that’s not a substitute for applying the patch.

CVE-2026-50661 (Windows BitLocker bypass). This flaw was publicly disclosed before the patch was ready. An attacker with physical access to a device could bypass BitLocker’s disk encryption. Microsoft says it hasn’t seen active exploitation yet, but the details are public, so the window is closing. Laptops used by travelling staff or remote workers are the main exposure here.

Why 570? The AI factor

The sheer volume of patches this month isn’t a sign things are getting worse. It reflects something Microsoft signalled earlier this year: the company is using AI-assisted vulnerability scanning across the Windows codebase. Microsoft itself warned customers that patch counts would rise as its automated tools find bugs faster than the traditional review cycle. Think of it as Microsoft doing more of the finding before attackers do.

That context matters for IT teams. A 570-patch release sounds alarming, but a large portion of these are vulnerabilities that were found internally and carry a low probability of real-world exploitation. The ACSC’s Essential Eight framework recommends patching internet-facing systems within 48 hours and other systems within two weeks. That triage approach still applies: not every patch needs to go out simultaneously.

The breakdown this month includes 254 elevation of privilege bugs, 145 remote code execution bugs, 59 rated critical, and dozens more across information disclosure, denial of service, and spoofing. Even excluding 468 separate Chrome/Edge vulnerabilities fixed by Google, it’s a heavy load.

What Brisbane businesses should do this week

For most small and mid-sized businesses, the action list is straightforward. If your IT consulting team manages updates for you, confirm they’ve prioritised the three zero-days and any critical-rated patches for internet-facing systems. If you manage your own IT, here’s where to start:

  • Patch SharePoint Server (CVE-2026-56164) first if you run it on-premises. This is network-exploitable and actively used in attacks.
  • Patch AD FS (CVE-2026-56155) as the next priority, particularly if staff use single sign-on to access Microsoft 365 or other services.
  • Check that laptops with BitLocker are updated, especially devices used by remote or travelling staff (CVE-2026-50661).
  • Run Windows Update on all devices and confirm cumulative updates are applying. Windows 10 devices in the Extended Security Update programme receive this month’s patches via KB5099539.
  • Review your SharePoint server logs for unusual privilege changes if that system has been internet-accessible.

One practical note: with a patch load this large, some organisations choose to test updates on a small group of devices before rolling out broadly. That’s sensible for complex environments. For most SMEs running standard Windows and Microsoft 365 setups, the risk of delaying patches outweighs the risk of a compatibility issue.

What this means for your security posture

Patch Tuesday is one part of staying secure, not the whole picture. A business that patches promptly but has no visibility into what’s happening on its network can still be compromised through credential theft, phishing, or an unpatched device that slipped through. We work with Brisbane and South-East Queensland businesses every day who have patching covered but still carry blind spots elsewhere.

The two actively exploited zero-days this month both rely on privilege escalation, which means an attacker already had some kind of access before using them. That’s a useful reminder that layered security controls matter: patching reduces the attack surface, but multi-factor authentication (MFA), monitoring, and access controls catch what patching can’t. If you want to understand where your environment stands, a security assessment is a practical starting point.

Frequently asked questions

Does this affect my Microsoft 365 cloud apps?

The majority of vulnerabilities in this release affect Windows operating systems, SharePoint Server (on-premises), AD FS, and other server products that require customer-side patching. Many Microsoft 365 cloud services are patched by Microsoft automatically. However, Windows devices that access those services still need their operating system updated.

We use SharePoint Online, not SharePoint Server. Are we affected?

CVE-2026-56164 targets SharePoint Server, which is the on-premises version. SharePoint Online (part of Microsoft 365) is managed and patched by Microsoft. If your business runs purely on SharePoint Online, this particular vulnerability doesn’t require action on your side.

What is a zero-day vulnerability?

A zero-day is a security flaw that attackers exploit before the vendor has released a fix. Once a patch is issued, it’s no longer a zero-day, but systems that haven’t applied the patch remain at risk. The urgency with zero-days is higher because working exploits are already circulating.

How often should we be patching Windows devices?

The ACSC’s Essential Eight recommends patching internet-facing systems within 48 hours of a critical patch release, and all other systems within two weeks. For most SMEs, a monthly patching cycle aligned to Patch Tuesday is a reasonable baseline, with critical zero-days actioned sooner.

What if we can’t patch immediately?

For SharePoint Server, Microsoft recommends enabling AMSI and setting Request Body Scan mode to Full as a temporary step. For BitLocker devices that can’t be patched right away, ensure physical security controls are in place for portable devices. These are stop-gaps only. Patching is the fix.

Where to from here?

If you’re not sure whether your systems received this month’s patches, or you want a clearer picture of your overall security posture, we’re happy to help. Get in touch with the TTA team and we’ll take a look.

Get tech tips

Stay up-to-date with the latest in tech for small and medium business.
Subscribe to our newsletter and get tips and monthly updates.